Sr Product Security Engineer

 
  • Business Unit: Draeger Medical Systems, Inc., Job-ID: 1352
  •  
  • Location: Andover
  • Function: R&D
  • Work Location: Hybrid
  • Employment Type: Permanent

 

 

The Job Responsibilities

We are hiring a Senior Product Security Engineer to work hybrid, 3 days a week, in our Andover, MA office.


The Senior Product Security engineer helps secure patient monitoring medical device solutions and connected health software throughout the product lifecycle. This role partners directly with systems, software, and test engineering teams to build security into product architectures, generate objective evidence for regulatory submissions, and maintain product cyber resilience after release.  


The selected candidate will support the integration of advanced cybersecurity controls, identify and mitigate vulnerabilities, and contribute to initiatives that improve cyber resilience across the product lifecycle. This person will serve as a technical subject matter expert, collaborate across functions, and help drive long-term improvements in product security posture. 


This is a product security engineering role; it is not focused on enterprise IT security. 


Main Responsibilities:

•    Product Security - Implement security requirements across the medical device development lifecycle by partnering with cross-functional teams and applying best practices from design through deployment. 
•    Perform threat modeling, attack-surface analysis, and product cybersecurity risk assessments. Define security requirements and risk controls, and integrate cybersecurity risks with product safety risk management. 
•    Support the design and delivery of secure medical devices through implementation of capabilities such as secure boot, secure communications, data protection, software update mechanisms, system integration protections, and access controls. 
•    Plan and review cybersecurity testing, including vulnerability scanning, software composition analysis, fuzzing, and penetration testing. Drive remediation and confirm closure through retesting. 
•    Maintain product SBOMs and assess reported vulnerabilities. Determine product impact, prioritize remediation, and support coordinated vulnerability disclosure and postmarket monitoring. 
•    Prepare and review cybersecurity documentation for FDA and other regulatory submissions. Respond to regulator and customer cybersecurity questions. 
•    Serve as a technical subject matter expert. Work with engineering, test, quality, regulatory, service, legal, and program management teams to resolve product security risks. 
•    Improve product security processes, tools, and reusable engineering practices based on emerging threats, standards, and regulatory expectations. 

Your Qualifications

Education 
Bachelor's degree in Computer Science, Cybersecurity, Computer Engineering, Electrical Engineering, Software Engineering, or a related technical field, or equivalent practical experience. 

 

Required Qualifications 
•    3 to 6 years of experience in product security, application security, embedded security, or security engineering in a product development environment 
•    Experience with threat modeling, cybersecurity risk assessment, secure design, vulnerability analysis, and security testing. 
•    Working knowledge of embedded, Linux, Windows, real-time, or network-connected systems, including common network security principles and protocols.
•    Understanding of secure development lifecycle and security-by-design practices.
•    Ability to communicate technical risks clearly, develop traceable documentation, and support multiple assignments in a cross-functional environment. 

 

Preferred Qualifications 
•    Experience developing or securing medical devices, safety-critical products, or products in another regulated industry. 
•    Experience supporting FDA and other global medical device cybersecurity submissions and responding to regulatory questions or deficiencies. 
•    Familiarity with IEC 81001-5-1, AAMI TIR57, applicable FDA cybersecurity requirements and guidance, NIST publications. 
•    Hands-on experience with secure product implementation, security testing, SBOM or software composition analysis tools, and vulnerability remediation. 
•    Programming or scripting experience and relevant cybersecurity certifications such as CSSLP, GPEN, or Security+.

 

The targeted pay range for this position is typically between $115,000 - $127,000. We note that the base pay offered is based on market location and may vary further depending on individualized factors for job candidates, such as job-related knowledge, skills, experience, and other objective business considerations. This position is eligible for the following additional compensation: annual pay. 

 

Dräger Benefits

At Draeger, Technology for Life means supporting our people in every aspect of their lives. We offer a competitive benefits package that may include:
  • Medical, dental, and vision insurance
  • Life, short- and long-term disability coverage
  • 401(k) with company match
  • Over 4 weeks of paid time off, plus holidays and parental leave
  • Flexible spending accounts and employee assistance program
 
Select locations also offer free parking, an on-site gym, cafeteria, and game room.
 
Talk to your Draeger recruiter to learn more!

 

Who we are

We’re hiring! If you want your contributions to make a real difference, check out this new career opportunity with us at Draeger where we are led by the guiding principle “Technology for Life”.
 
Draeger has several sites located across North America as well as field-based sales and service positions. Our North America headquarters is located in Telford, PA just north of Philadelphia. We also have US sites in Andover, MA, and Houston, TX. Our Canada site is located in Mississauga, Ontario.
 
Draeger is an Equal Opportunity Employer.

 

Interested?

Please, apply directly through our career portal.
We look forward to receiving your application.




Nearest Major Market: Boston